US-CERT has received a report today, indicating that extensive attacks and system compromises (exploit unknown at this time) have originated from the following IP addresses.
200.128/16
200.222.216.133
200.149.99.228
Very little technical detail is available at this time. US-CERT requests that each recipient check your logs from 1 Jan 05 to present. Provide US-CERT or Control Systems Center your results either positive or negative.
Preliminary analysis indicates that the activity initiated from these IPs appear to have been made by a group rather than an individual. More than 526 exploit attempts have been noted. The attacks seem to have targeted specific IPs, not ranges of IPs. Only servers were attacked. No desktop machines were observed to be scanned or targeted for attack. Initial attacks were automated, followed by manual hands-on attacks. All of the attacked servers were running a Microsoft Windows Operating System and at least one was fully patched when compromised.
Please disseminate to your owner operators ASAP so US-CERT can judge the national impact of these compromised systems.
Please review any contact with the above systems through logs, fw's, and IDS's and report back through the ISAC or directly to US-CERT or me directly at
[email protected]. I cannot stress enough the seriousness of these attacks. Response teams have been deployed to deal with system compromises from NCSD.
best regards,
David N Sanders
Director, Control Systems Center
National Cyber Security Division
Department of Homeleand Security
703-915-8769
703-235-5193